Friday, August 9, 2013
What the Hell is Happening to My Country, Part 49,924...
Lavabit gained some notoriety recently because allegedly Snowden used it. There's lots of speculation in the press about what provoked Lavabit's shutdown. I think it's likely they were the recipient of a National Security Letter (NSL) requiring them to turn over metadata they thought should be private.
I want to focus on something other than Snowden's use of it, and the probably-not-coincidental appearance of an NSL. I want to focus on the wrongness – the un-Americanness – of a mechanism like the NSL. I (and many others) think it's a step way, way over the line between privacy and security. It's also a gold-plated invitation for abuse, as the victim has no recourse at all – he can't even tell anyone (not even a lawyer!) what his problem is. That's just wrong. Even if you believe that Snowden was a traitor, even if you believe our government needs a way to snoop on this data...it's still wrong. It's the wrong way to solve the problem, even if you believe there is a problem.
The existence of NSLs is one of the (unfortunately) many things happening to America in my lifetime that have started to make me wonder if this really is the best country for my family and I to be citizens of. Before about 10 years ago, I had never had such a thought in my life...
Wednesday, February 13, 2013
Passwords Are Not the Bottleneck...
Tuesday, September 18, 2012
Of All the Possible 4 Digit PINs...
I guessed which one was most popular (“1234”), but not the least. Most of all I was surprised by the shape of the curve of most popular to least popular PINs. I was also intrigued to see the use of heat maps (like the one at right), a technique I first learned about in the '80s as one of the more effective quick tests of a random number generator. Altogether a very nice analysis by Nick Berry at DataGenetics...
Friday, July 20, 2012
Crypto vs. Rubber Hose...
The basic idea is that you can learn subconciously (in fact, this is the way we learn most things), without even realizing that you've learned something. Passwords are not like this; those we very conciously learn (memorize).
The new technique involves learning how to play a special game. In the process of doing this, you learn – subconciously – a 30 character password made up of just six characters. This is a very secure password. If someone asked you to recite it, you wouldn't be able to do it – not even if they gave you the rubber hose treatment, and not even if you wanted to give them the password. You are not concious of it at all. To actually authenticate yourself to a computer, you have to play a round of their game. In doing so, you demonstrate to the computer that subconciously you really do know the password.
You might ask yourself (I certainly did) “But how does this help with the rubber hose attack? The trained authenticator could still be forced to play the little game!” The authors of the paper assert that there must be a “liveness test” – in other words, you can't use their method for remote authentication, but rather only for authentication when physically present at the system you're trying to authenticate to. Presumably someone would then notice if you were being beaten with the rubber hose. There are some problems with that, as there are ways to coerce people that don't require the coercer to be physically present with the coerced (for example, your spouse or child could be held hostage until you authenticate). Worse, I think, is that if you subject a password authentication system to a liveness test, then its security is enhanced in the same way. In other words, it seems to me that a large part of the benefit of this new system is derived from the liveness test, rather than the method itself.
But all that carping aside, there are some genuinely interesting security ideas in here. How practical they are is another matter altogether, but the general notion of using subconcious memory strikes me as worth exploring.
Authentication to a computer system is a really tough problem, far harder than most people realize. It's the basis for many of the kinds of computer security that average people run into every day (like, say, access to your bank account) – and yet we are still lacking good, secure, reliable solutions. Passwords are by far the most common approach, and they are demonstrably feeble. Biometric authentication (fingerprints, iris patterns, etc.) are stronger, but are defeatable and less reliable than most people consider acceptable. So I'm always interested in anything that might improve the situation...
Monday, June 18, 2012
Friday, June 15, 2012
Who Benefits from the Recent Avalanche of Security Breaches?
The Obama administration recently appointed to special prosecutors to track down and squash these leaks. Nobody seems to expect these prosecutors to actually accomplish anything; almost universally the body politic sees these as a sop to the ignorant masses and a way for Obama to be seen as taking command of the situation.
Why would this be seen so universally as a charade? Peggy Noonan puts her finger on it exactly. Anybody looking at the situation, including the pajama-clad blogging masses, can see one fact plain as day: the beneficiary of these leaks is, without exception, Barack Obama. Faced with such a clear pattern, you don't have to be very cynical to suspect political, self-serving shenanigans are at work – or to believe that the appointment of the special prosecutors is a cynical charade designed to appease an ignorant public. Also, unfortunately, one can be forgiven for suspecting that the charade will work...
Thursday, June 14, 2012
Top Ten Hacked LinkedIn Passwords...
link, 1234, work, god, job, 12345, angel, the, ilove, sexNot exactly a creative bunch! Several of those I might have guessed within a few minutes. Probably within a few hours I'd have guessed them all. I can imagine that many people wouldn't feel particularly concerned about the security of their LinkedIn account – it's not like a bank account or something. But still – with passwords that weak, there's really not much reason to have a password at all! And it wouldn't take much effort to do much better...
Tuesday, April 10, 2012
Mosh, the Mobile Shell...
Friday, March 30, 2012
Airport Security Debate: Bruce Schneier Kicks Butt!
This house believes that changes made to airport security since 9/11 have done more harm than good.Defending the motion: Bruce Schneier, who should be well known to readers of this blog.
Opposing the motion: Kip Hawley, former TSA Administrator.
The debate has been lively. For me, the arguments were familiar; the debate has essentially been held in a much less formal way over the past several years, through the many writings of Schneier, Hawley, and many others. It's been a real pleasure to see Mr. Schneier make his arguments, though – he's got a real flair for exposition.
The debate is now over, though. The motion has been carried: 89% of the votes were “aye”. Mr. Schneier carried the day, rather dramatically. Adam Barnes was the moderator. An excerpt from his announcement of the winner:
Voters have roundly declared that the frustrations, the delays, the loss of liberty and the increase in fear that characterise their interactions with airport-security procedures vastly outweigh the good these procedures achieve. For some, indeed, the benefits are essentially non-existent: any sensible terrorist can find a work-around or choose a different point of attack, as Bruce Schneier explains. And so the widely expressed hope is that changes made to security in the (near) future will make the whole regime less reactive, more rational, more flexible and more intelligence-driven. The results of this debate suggest that these changes should be made with some urgency: passengers are angry.Now if only our (insert your own epithets) Congresscritters would listen up.
Wednesday, March 28, 2012
Passwords...
These days, the most common passwords fall into one of three categories.
First there are the stupid, easy passwords, such as "password123" or "qwerty". An amazing number of people (by some accounts, over 20%) use such passwords for things they really care about, like their bank account. This is like removing the lock from your house. If you do this, you shouldn't be allowed to touch a computer. The bad guys have readily-available lists of common stupid passwords, and they will try them all to see if they work.
Then there are the passwords comprised of personal information of some kind: your kid's name and birthday, or the names of your two dogs, etc. If these are well-chosen, and if (this is a huge if) the attacker has no other information about you, these kinds of passwords can be reasonably secure. But you need to be very certain that the personal information you disclose isn't available electronically anywhere: not on Facebook, not at your bank, not even on your tax return. A bad guy who hacks into your Facebook account might well know your kids names and birthdays. The safest things to use for this kind of password are generally things in your distant (and hopefully pre-Internet) days. Say, for example, the name of your fourth grade teacher (I'm looking at you, "Mrs.Dalrymple4th"). Good passwords of this type are relatively uncommon, though – most people make poor choices with easily discoverable or guessed information.
Finally, there are the passwords comprised of some memorable sequence of words, like "JamulGeekGeezer". People, especially non-technical people, are attracted to these passwords. They look secure, mainly because they're long and they look unlikely. The problem is that they are usually made up of words from a relatively small list of common words: a few tens of thousands of ordinary words and place names. That may sound like a lot of words to you, but to a computer this is a small list. Most web sites don't have protection against an attacker trying thousands of passwords, so the bad guys simply try lots of combinations of these words from their “dictionary” of common words. These attacks are depressingly effective. A common variant of this type of password replaces all "o" characters with "0" (zero) characters, "s" with "$", or some such thing. There are also relatively few variations of these, and the bad guys have dictionaries of them as well. A more secure variation of this type deliberately misspells one or more words, like "JamulGekkGezzer". That's far more secure, as the misspelled words are not likely to be in the dictionary.
Years ago, I read about another technique (mentioned in the linked article) that yields passwords that are both memorable and secure. I've been using it ever since. The technique is simple. First, choose a phrase that is easy for you to remember, but is unlikely for anyone else to ever use or guess. For example, I might choose "Miki is playing outside my red-roofed house." You must be careful, when choosing a phrase, not to use some famous lines from movies or plays, etc. – those an attacker could certainly guess. Then apply some simple rule (also easy to remember) to turn that phrase into a password. For example, I might have the rule "Take the first letter of each word, plus any punctuation". That would yield the password "Mipomr-rh." Now that's a pretty secure password. It's reasonably long (10 characters; a little longer would be better) and it certainly isn't attackable by a dictionary attack. I've been recommending this to anyone who asks me, and I still recommend it. For passwords protecing things that are really valuable to me, I use passwords with 12 or more characters, created from phrases like I used above.
Monday, January 16, 2012
Israeli Security Development...
TEL AVIV, Israel The Israelis are developing an airport security device that eliminates the privacy concerns that come with full-body scanners. It's an armored booth you step into that will not X-ray you, but will detonate any explosive device you may have on your person.
Israel sees this as a win-win situation for everyone, with none of this crap about racial profiling. It will also eliminate the costs of long and expensive trials.
You're in the airport terminal and you hear a muffled explosion. Shortly thereafter, an announcement: Attention to all standby passengers, El Al is proud to announce a seat available on flight 670 to London. Shalom!
Saturday, December 17, 2011
Sovereign Keys...
Friday, March 18, 2011
RSA Hacked: Not Good...
The RSA SecurID system is, I believe, the most widely deployed two-factor authentication system. I've worked at several companies that use it (including my current company), and many of our customers use it as well. Any practical compromise of this system would be quite a large security hole...
Thursday, December 16, 2010
How to Safely Store a Password...
Thursday, November 11, 2010
Monday, January 5, 2009
Security Theater...
Michael Yon, one of my favorite sources for information about the War on Terror, tells the story of a recent encounter with the DHS by one of his friends, a Thai woman named Aew. Here's his conclusion:
When I discovered that she had missed her flight, after about 24 hours of travel thus far, I called immigration at Minneapolis and asked to speak with Officer Knapp. Knapp got on the phone, but this time it was me questioning him. Knapp told me it was legal to read e-mails. I asked for his first name, but he was afraid to give his first name, which was rather strange for someone working within the confines of an airport where everyone has been searched for weapons. Where I work, in a war zone, soldiers give their first and last names and face Taliban and al Qaeda heads up, man to man. I write about al Qaeda, Taliban and other terrorist groups who kill thousands of people. My name is Michael Yon. My first name is Michael. Mr. Knapp hides behind a badge bullying a woman whose only activities are Yoga, reading, travel, and telling me what is healthy and unhealthy to eat. Knapp is a face of Homeland Security. How many other officers at Homeland Security bully 90-pound women, but are afraid to give their own names?Ouch.
Knowing that Homeland Security officers are creating animosity and anxiety at our borders does not make me feel safer. How many truly bad guys slip by while U.S. officers stand in small rooms and pick on little women?
I have just returned from Afghanistan and Iraq on a trip with U.S. Secretary of Defense Robert Gates, and I can assure you that we can do better. We do not have to violate human rights and insult our closest allies to maintain our security.
Meanwhile, Aew had missed two flights; standby seats were full on the second flight, and I was considering flying from Florida to Minneapolis to get her myself. I did not want Aew to have to sleep in the airport overnight.
I had intended to show Aew a bit of my country. But it's taking a little while for her to get over her discomfort at being in America. She was treated better in China. So was I.
Security theater may be popular with the politicians, but it's not real popular with people on the ground. When a security hawk like Michael Yon starts decrying the uselessness and unfairness of a policy, you know there's something wrong with it...
500 Most Common Passwords...
Now someone has published a list of the 500 most common passwords. My passwords are not on this list. Are yours? If so, you're easy prey for any hacker...
Thursday, February 23, 2006
Danger!
You’re probably thinking that it’s faceless hackers, Muslim extremists, Karl Rove, or James Carville. Nope — statistically those people are very unlikely to be the source of anything that hurts your computers. Well, then who is the most likely?
Your friends.
That’s right, your friends — the ones who email you those funny video clips, or the tear-jerker animal presentations. They are helping the real bad guys (who need red-hot pokers in their rectums) spread their evil. Of course your friends don’t know they’re helping the bad guys, but they are.
And so, most likely, are you. Because, like the vast majority of innocent email users, you (like me) forward those cute movies, those funny foreign advertisements, etc. to your friends.
And some of those attachments are bad.
How can you tell? Don’t anti-virus programs catch all those things?
No, they don’t. They catch some, to be sure. I use anti-virus software on my system, because I know it will catch a lot of the bad stuff. But I also know that it misses things — it misses the newest variations of viri, worms, and spyware. It will also miss the more sophisicated variations, especially the “polymorphic” ones that change constantly, specifically to evade anti-virus software.
But, you say “I would never forward an attachment to someone after it infected my system!” Well, I would hope not. But here’s the rub: you won’t know your system is infected! You see, the evil hackers (may they be plagued by incurable whole-body acne) who write these things understand quite a bit about human behavior.
There are many ways for them to fool you. One of the most common is the “time bomb": they tell their evil software not to do anything bad until some specific date, or until after it’s been installed on your system for some time — plenty of time for you to have forwarded it to all your friends. Another category of evil software simply hides itself, trying hard to never do anything that would bring itself to your attention. That’s because it’s quietly watching all your keystrokes — including when you enter your credit card number for online shopping, or your username and password to your bank account. Then it sends the interesting stuff back home to the scum who wrote the software.
How can you protect yourself against this? Especially if you’re not technically saavy?
The truth is there’s not much you can do. Even being technically saavy isn’t enough — to detect the best of the evil software (fortunately this is the small minority of it), you need to be a specialist with the right knowledge and tools. And you’d have to spend a lot of time, constantly, checking and rechecking your system. It’s a little bit like taking a walk. Someone evil could be lurking behind almost anything. You can improve your chances by being careful where you walk (a walk in San Diego’s Balboa Park is very safe when compared with a walk in San Francisco’s notorious “Tenderloin” district). Likewise, you can try to be careful with the attachments you open. Some of them (for instance, any that end with .EXE, .COM, or any of a few dozen other “extensions") are inherently dangerous, and should be avoided unless you know absolutely for sure that they are safe.
But with such advice, we’re already assuming some degree of tech saavy. Most non-technical people I know have already just given up on this — they either never open email attachments, or they always open them. In the latter case, they’re just hoping that nothing evil comes their way. And aside from running anti-virus software, and keeping it up to date, there’s little I can do to help them out. Chances are that one of these days they’re going to discover that some pimply ex-Soviet bloc teenager has their credit card number, or a Mulim fanatic in Iran has their street address and phone number, or … substitute your own nightmare.
The reality is this: if we want to enjoy the use of this modern technical marvel (the personal computer), we have to accept some level of risk — much as we accept the risk of an accident as the price we pay for enjoying the use of our car. There are things we can do to help mitigate the risk — we can spend money on anti-virus software, firewalls, etc., and we can educate ourselves. This is much like having seat belts and airbags in our cars, and learning defensive driving skills. And we can even try to “drive” our personal computers in better neighborhoods (e.g., be a little selective about exactly what email attachments you open). But we can’t make it completely safe to use a PC…
Tuesday, February 21, 2006
Security Hole
Update: Welcome, visitors from Pajamas Media! The number of people visiting my corner of cyberspace jumped this afternoon because of a link those nice folks posted this afternoon. I hope that while you’re here, you’ll look around a little. There are lots of things to explore here, from political scribblings, science and technology thoughts, to photos of our travels and our collection of animals. And much more!
Update II: Will wonders never cease? Now there’s a link (broken at the moment <sob>) to this post from Instapundit! Assuming Glenn fixes that link, I suspect I’ll have even more visitors. Welcome, one and all — please take a look around while you’re here!
Bruce Schneier has a wonderful little story on his blog (original article here) about a test of an attack method that combines technical means and a little social engineering. It’s a clever exploit that (unfortunately) is just one example of bazillions of possible clever exploits. In this one, the testers went onto the streets of London and handed out CDs that supposedly contained a Valentine’s Day promotional. Many of the people who were given the CDs carried them straight into their (allegedly “secure") offices and ran the programs right of the CD. Any IT guy could tell you that by doing so, they bypassed nearly all of the security measures the companies had in place; had the software been hostile, it could have done a lot of damage — either by stealing confidential information, modifying critical information, or even by taking down internal systems.
Not good. And oops.
The original article basically blames the employees' bad security attitude, or lack of security education. Bruce draws a better lesson: that the real problem is insecure infrastructure. While I agree with every one of Bruce’s points, in a practical sense it doesn’t seem likely that they’re going to be addressed anytime soon. To use Bruce’s example, this particular attack could have been prevented by not giving every employee a worksation or laptop that could just run any old software from a CD. True enough. But … I don’t know any company that is actually going to run out and put that restriction in place…
I’ll draw another (fairly obvious) lesson from this story: that many IT organizations are throwing their security money at the wrong problems. In particular, except in the most sophisticated IT security environments, the emphasis is almost 100% on “border security": firewalls, multi-element identification, etc. And almost nothing is done about security inside the firewall — even though it’s demonstrable that the biggest threats for most companies are of internal origin. The CD attack is a great example, though theoretical. Already happening are worm and virus attacks — and many (I suspect most) companies are woefully unprepared for these. I’ve worked at two companies — and I know of many more — where all the company’s servers are fully exposed to the LANs that host the company’s workstations. That means that any worm or virus that infected a workstation has free access to those servers — and in these days of laptops and employees VPNing in from home, if you’ve got more than about three employees, the chances are pretty good that some of them are infected. The fact that more damage isn’t done this way is testament to the bad design of worms and viri, not that the risk doesn’t exist.
Yet changing the way company’s secure their IT infrastructure isn’t easy, as my personal experience attests. I’ve had one boss (the CEO) who, after my presentation of things we needed to do to secure ourselves internally, said “Let’s just get SecureID!”. When I told him that would be like putting a padlock on a wet paper bag, he countered with “I don’t care if it really does anything — what I care about is how secure we’ll appear to our customers.” Customers who are, more than likely, equally uninformed about security. This company ended up doing precisely nothing about internal security, despite my tiresome railing on the subject. And to this day they have not been hit with any big problems, which reinforces that illogical behavior. Sometimes I’ve thought that a small “demonstration” was in order, just for the educational value…
I don’t have any good answers for this challenge. My suspicion is that it’s similar to corporate behavior with respect to backups: the issue will be ignored until the company gets burned, then it will be addressed. Companies sometimes seem to be incapable of learning from the pain of others…



